SPIDERFOOT
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Open-source OSINT automation tool that queries 200+ data sources to build intelligence on targets (IPs, domains, emails, names, etc.).
INSTALLATION#
# pip pip install spiderfoot # From source git clone https://github.com/smicallef/spiderfoot cd spiderfoot pip install -r requirements.txt # Docker docker pull spiderfoot/spiderfoot docker run -p 5001:5001 spiderfoot/spiderfoot # Kali Linux sudo apt install spiderfoot
STARTING SPIDERFOOT#
# Web UI (recommended) python3 sf.py -l 127.0.0.1:5001 # Access at: http://127.0.0.1:5001 # CLI mode (headless) python3 sfcli.py # With custom config python3 sf.py -l 0.0.0.0:5001 -d /path/to/spiderfoot.db
WEB UI WORKFLOW#
1. New Scan: click "New Scan" 2. Enter target (domain, IP, email, name, etc.) 3. Select scan type: - All: every module (slow, comprehensive) - Footprint: passive recon - Investigate: deeper analysis - Passive: no direct target contact - Custom: pick specific modules 4. Start scan 5. Browse results in tabs (Data, Graph, Status)
SCAN TYPES#
# Footprint (passive reconnaissance) - DNS, WHOIS, certificate transparency - Web scraping, social media - No active probing of target # Investigate (moderate depth) - Footprint + some active checks - Port scanning, web crawling - Banner grabbing # Passive (zero target contact) - Only queries third-party sources - No packets sent to target - Safe for initial recon # All (comprehensive) - Every available module - Active + passive techniques - Longest scan time
TARGET TYPES#
- Domain name: example.com - IP address: 1.2.3.4 - IP subnet: 10.0.0.0/24 - Email address: user@example.com - Phone number: +1234567890 - Person name: "John Smith" - Username: jsmith - Bitcoin address: 1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa - ASN: AS15169
CLI MODE#
# Run scan from command line python3 sfcli.py -s target.com -t all # Specific modules python3 sfcli.py -s target.com -m sfp_dns,sfp_whois,sfp_shodan # Output formats python3 sfcli.py -s target.com -t passive -o json > results.json python3 sfcli.py -s target.com -t passive -o csv > results.csv # Quiet mode python3 sfcli.py -s target.com -t passive -q
KEY MODULES (200+ AVAILABLE)#
# DNS & Domain sfp_dns # DNS resolution and records sfp_dnsbrute # DNS subdomain brute force sfp_dnsresolve # DNS resolution sfp_dnsdumpster # DNSDumpster lookup sfp_dnszonexfer # DNS zone transfer attempt sfp_subdomain # Subdomain discovery sfp_crt # Certificate Transparency logs # Network sfp_portscan_tcp # TCP port scanning sfp_portscan_basic # Basic port scan sfp_shodan # Shodan search sfp_censys # Censys search sfp_binaryedge # BinaryEdge search sfp_greynoise # GreyNoise intelligence # Web sfp_spider # Web spider/crawler sfp_webanalytics # Web analytics IDs sfp_webframework # Web framework detection sfp_wappalyzer # Technology detection # Email sfp_emailformat # Email format discovery sfp_hunter # Hunter.io email lookup sfp_emailcrawlr # EmailCrawlr lookup sfp_haveibeenpwned # HIBP breach check # Social Media sfp_social_media # Social media profiles sfp_instagram # Instagram lookup sfp_twitter # Twitter lookup sfp_github # GitHub repos and users # Reputation & Threat Intel sfp_abuseipdb # AbuseIPDB reputation sfp_virustotal # VirusTotal lookup sfp_threatminer # ThreatMiner lookup sfp_maltiverse # Maltiverse threat intel sfp_alientvault # AlienVault OTX sfp_ibmxforce # IBM X-Force sfp_urlhaus # URLHaus malware URLs # WHOIS & Registration sfp_whois # WHOIS lookup sfp_builtwith # BuiltWith technology sfp_bgpview # BGP/ASN info # Data Leaks sfp_haveibeenpwned # HIBP breach check sfp_dehashed # Dehashed leak DB sfp_leakix # LeakIX exposure data sfp_snov # Snov.io email intel # Geolocation sfp_geoip # GeoIP lookup sfp_ipinfo # IPInfo lookup
API KEY CONFIGURATION#
# Settings > API Keys (Web UI) # Or edit: ~/.spiderfoot/spiderfoot.conf # Common API keys to configure: Shodan # Internet device search Censys # Host/cert search VirusTotal # File/URL/domain analysis Hunter.io # Email finder HaveIBeenPwned # Breach data SecurityTrails # DNS/domain intelligence BinaryEdge # Internet scanning data FullContact # People/company data Clearbit # Company enrichment Builtwith # Technology detection IPInfo # IP geolocation AbuseIPDB # IP reputation AlienVault OTX # Threat intelligence GitHub # Code/user search Dehashed # Leaked credentials GreyNoise # Internet scanner intel
RESULTS ANALYSIS#
# Data Browser - Browse all findings by data type - Filter by module or entity type - Export as CSV/JSON # Graph View - Visual relationship graph - Shows connections between entities - Click nodes for details - Useful for identifying relationships # Correlations - Cross-module correlation - Same data found by multiple sources = higher confidence - SpiderFoot links related entities automatically # Data Types Found - IP addresses, subnets, ASNs - Domain names, subdomains - Email addresses, phone numbers - Usernames, person names - Web technologies, frameworks - Open ports, services - SSL certificates - Social media profiles - Data breaches, leaked credentials - Malware associations - Physical locations (GeoIP)
SPIDERFOOT HX (CLOUD)#
# Commercial hosted version: https://hx.spiderfoot.net # Features: - Scheduled/recurring scans - Team collaboration - More data sources - Case management - No infrastructure to manage
AUTOMATION EXAMPLE#
#!/bin/bash
# Quick passive recon script
TARGETS="target1.com target2.com target3.com"
for target in $TARGETS; do
python3 sfcli.py -s "$target" -t passive -o json > "${target}_recon.json"
echo "Completed: $target"
done
TIPS#
- Start with Passive scan to avoid alerting the target - Configure API keys for much richer results - Shodan + Censys + VirusTotal APIs are most impactful - Graph view reveals hidden relationships between entities - Use CLI for automation and scripting - Docker deployment is easiest for quick setup - Scan results persist in SQLite database - Re-run scans to track changes over time - Combine with manual OSINT for best results - Export to CSV for processing in other tools